Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CLSA-2026-1777946894 — idle-python2.7 (CVE-2022-0391 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Fix CVE(s): CVE-2022-0391, CVE-2022-45061, CVE-2024-7592, CVE-2026-4519

  • SECURITY UPDATE: URL parsing accepts ASCII tab/CR/LF (URL smuggling)
  • debian/patches/CVE-2022-0391.patch: sanitise tab, CR, LF anywhere in

URL/scheme inside urlsplit() before cache lookup, plus regression

test in Lib/urlparse.py, Lib/test/test_urlparse.py.

  • CVE-2022-0391
  • SECURITY UPDATE: Quadratic complexity in IDNA decoding (DoS)
  • debian/patches/CVE-2022-45061.patch: replace O(n) outer loop with a

single any() guard in nameprep(), plus regression test in

Lib/encodings/idna.py, Lib/test/test_codecs.py.

  • CVE-2022-45061
  • SECURITY UPDATE: ReDoS in Cookie._unquote (quadratic backslash parsing)
  • debian/patches/CVE-2024-7592.patch: replace the quadratic _OctalPatt

/ _QuotePatt loop with a single linear re.sub-based decoder, plus

regression tests in Lib/Cookie.py, Lib/test/test_cookie.py.

  • CVE-2024-7592
  • SECURITY UPDATE: webbrowser.open() argument injection via leading dash
  • debian/patches/CVE-2026-4519.patch: add BaseBrowser._check_url() and

call it from every browser open() to reject URLs whose first

non-whitespace char is '-', plus regression test in Lib/webbrowser.py,

Lib/test/test_webbrowser.py. Also backports upstream gh-148169

(commit d22922c8a7) to close the %action-substitution bypass: the

check is deferred until after %action substitution and the per-arg

replace() chain is reordered (%action before %s) so an attacker

cannot smuggle a leading dash via the URL.

  • CVE-2026-4519
  • BUILD: replace libdb-dev (<< 1:6.0) with libdb5.3-dev in

debian/control{,.in} so the build pulls the explicit Berkeley DB 5.3

development headers available on Ubuntu 20.04 ESM, instead of the

virtual libdb-dev package that is no longer satisfied in the ELS

build environment.

Affected software

CLSA-2026-1777946894 is recorded against 11 packages.

  • idle-python2.7 (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • libpython2.7 (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • libpython2.7-dev (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • libpython2.7-minimal (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • libpython2.7-stdlib (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • libpython2.7-testsuite (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • python2.7 (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • python2.7-dev (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • python2.7-doc (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • python2.7-examples (fixed in 2.7.18-1~20.04.7+tuxcare.els1)
  • python2.7-minimal (fixed in 2.7.18-1~20.04.7+tuxcare.els1)

Timeline and source

Published on 5 May 2026 and last revised on 4 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

errata.tuxcare.com (Advisory)

Other advisories for this package

idle-python2.7 has other advisories on record. If you are patching this one, these are worth checking on the same host:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-05-05
Updated 2026-08-20
Modified 2026-06-04
Fix URL N/A

Affected Packages

Software From version Fixed in
idle-python2.7 2.7.18-1~20.04.7+tuxcare.els1
libpython2.7 2.7.18-1~20.04.7+tuxcare.els1
libpython2.7-dev 2.7.18-1~20.04.7+tuxcare.els1
libpython2.7-minimal 2.7.18-1~20.04.7+tuxcare.els1
libpython2.7-stdlib 2.7.18-1~20.04.7+tuxcare.els1
libpython2.7-testsuite 2.7.18-1~20.04.7+tuxcare.els1
python2.7 2.7.18-1~20.04.7+tuxcare.els1
python2.7-dev 2.7.18-1~20.04.7+tuxcare.els1
python2.7-doc 2.7.18-1~20.04.7+tuxcare.els1
python2.7-examples 2.7.18-1~20.04.7+tuxcare.els1
python2.7-minimal 2.7.18-1~20.04.7+tuxcare.els1

Free Vulnerability Check

Is your site affected by CLSA-2026-1777946894?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CLSA-2026-1777946894 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesChainguardChainguard 2026